Stupid issue on my part I’m sure but I’m stumped. I have a couple of FreeNAS/TrueNAS boxes set up as inputs. When I select Show received messages I can see the syslog messages coming in. (TrueNAS uses syslog-ng)
I created a stream with the most basic rule I could think of to try to get the TrueNAS syslog events coming in.
sourcemust match input FreeNASUDP
When I view the messages directly on the Input It shows me that the message is being routed to the appropriate stream. Testing the rules manually also shows a success, but when I go to view the stream, it is always empty, and shows no messaged coming in or out.
I have no clue what I am missing here.
Is there a better solution for capturing FreeNAS/TrueNAS logs? Am I missing extractors?
I was able to set up streams from our Windows systems using winlogbeats without an issue.
Not that I know of, It took me 3 minutes to test your issue which I found none.
So, its not clear how your configuration are.
Out of curiosity, when you execute a manual search (from your picture you posted above) can you open one of the logs and show the left side?
What I’m wanted to see it this